Mirai Botnet Propagation and Exploitation of CVE-2025-24016
The Mirai botnet continues to spread as operators repurpose old source code and exploit newly published vulnerabilities. The CVE program, while beneficial, sometimes inadvertently highlights overlooked vulnerabilities. Researchers' attempts to educate through PoCs often lead to negative outcomes, emphasizing the importance of timely patching. CVE-2025-24016 affects active Wazuh servers running outdated versions, and patching to version 4.9.1 or later is highly recommended. The report includes IOCs, Snort rules, and Yara rules for two Mirai-based botnets, detailing their C2 infrastructure, malicious domains, and file hashes.
Pulse ID: 68fa3038f13a0c5ff5957e83
Pulse Link: https://otx.alienvault.com/pulse/68fa3038f13a0c5ff5957e83
Pulse Author: AlienVault
Created: 2025-10-23 13:40:08
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Mirai #OTX #OpenThreatExchange #Outcomes #PoC #RAT #RCE #bot #botnet #AlienVault